Privacy Policy — FiveBot
Version 1.3 · Effective date: 2026-09-05
This policy explains how SDN Ventures LLC ("we") processes personal data in connection with FiveBot. It is written to be read by two audiences: community owners (our customers) and community members (players and staff of the Discord servers our customers run).
1. Two roles — who is responsible for what
- We are the controller for: your account (dashboard sign-in), billing, and our own website analytics-free operations.
- We are the processor — your community's owner is the controller — for
the community data the Service handles on their behalf: tickets,
applications, moderation records, recorded administrative conversations,
and NPC conversations. For that data, direct your requests to the community
owner first; we support them under the DPA, and the in-product
/gdpr exportand/gdpr deletecommands work from day one.
2. What we process, why, and on what basis
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account: Discord ID, username, avatar, email | Sign-in, account management | Contract | Life of account |
| Billing: plan, invoices, payment status (cards handled by Stripe — we never store card numbers) | Payments, tax law | Contract; legal obligation | Statutory retention |
| Ticket content: messages inside ticket channels/threads only, form answers, ratings | Operating the support system, permanent transcripts | Processor, on the owner's instructions | Until erasure request or org offboarding |
| AI processing records: which knowledge chunks produced which answer, cost, confidence | Transparency ("why did the AI answer this way"), abuse and billing control | Processor | With the ticket record |
| Applications (whitelist/recruitment) | Reviewing applications | Processor | Per owner settings |
| Moderation cases and report evidence (clips/screenshots) | Moderation with evidence | Processor | Evidence: min(decision + org window, upload + 180 days) — enforced by an automatic sweep |
| Recorded administrative conversations (Bodycam) | Transcript + summary + conduct review of admin–player conversations | Processor; recording happens only in channels the owner marked administrative, and only after a notice is posted in that channel saying so — staying in the channel after that notice is the consent, and leaving, or pressing the opt-out button, means nothing of yours is recorded. No notice → no recording | Transcript: as ticket content. Audio: not stored — transcription happens in-flight; a narrow, owner-enabled evidence option stores audio under the evidence retention rule above |
| NPC conversations | In-game AI characters | Processor | Transcript: as ticket content. Your voice audio is never stored — speech-to-text happens in-flight |
| Ban network entries | Cross-community protection against ban evasion (opt-in per community) | Processor; owner's legitimate interest (community safety) | Identifiers are pseudonymized (keyed hashes) — never raw IDs; reports decay in weight over time, can be retracted, and support appeals |
| Talent scout signals (opt-in, marked channels only) | Suggesting community members who already help others, so an owner can consider inviting them to their team | Processor; off unless the owner turns it on, and then only in channels they have explicitly marked | Message content is never stored — it is read in memory, assessed, and dropped. What is kept is the assessment: a score, the rule it matched, and a reference to the message so the owner can check it. Removed on erasure, and the owner can delete any entry |
| Anti-abuse counters (message frequency) | Anti-spam | Processor | Sliding window in memory/Redis — message content is never stored by this feature |
| Aggregated question patterns | Improving starter knowledge bases | Anonymized at collection — never traceable to a person or a community; owners can opt out | N/A (anonymous) |
We do not sell personal data, run advertising, or track you across other sites.
3. AI processing
AI features send the necessary text (never voice audio) to our AI subprocessors — OpenRouter, which routes each request to the model provider for that request's tier: Google (Gemini) for the default tiers and Anthropic (Claude) for the escalation tier, as listed in §5 — to generate answers, translations, summaries, and NPC dialogue. Prompts and outputs are not used by us to train foundation models. Conduct reviews of staff conversations are proposals shown to humans; no automated decision with legal or similarly significant effect is made about anyone.
4. Voice — the specifics, stated plainly
The full, player-facing version of this section is a document of its own: Voice Recording Notice, which is what the bot links to from inside the voice channel. In short:
- The bot records only in channels the community owner marked as administrative, and only after posting a notice in that channel saying the conversation is being recorded, what happens to it, and how to opt out. If the notice cannot be posted, nothing is recorded.
- Consent is given by continuing to take part after that notice — the standard mechanism for recorded support and administrative conversations — and there are two ways out, both immediate: leave the channel, or press "Do not record me", which drops that person from the recording for the rest of the conversation, including whatever they were saying at the time. Someone who joins later is posted the notice again, for themselves, before their voice is captured.
- Audio is transcribed in-flight on our own infrastructure (no external speech-to-text provider) and is not saved as audio by default. What remains is the transcript, which both sides of the conversation receive.
- Voice data is never used for biometric identification, and no voiceprint or other voice template is created or stored — not for identification, not for authentication, not for anything else.
- Conduct reviews assess the staff member's handling of the conversation against a standard the community owner wrote. No decision about anyone is made automatically; see §3.
5. Where we are established, subprocessors, and transfers
We are established outside the EEA. SDN Ventures LLC is incorporated in Wyoming, USA. The infrastructure that actually holds community data is in the EU (Hetzner, Germany/Finland), but our own access to it from the US is itself a transfer, and we treat it as one.
| Subprocessor | What for | Location |
|---|---|---|
| Hetzner Online GmbH | Hosting (application, database, AI infrastructure) | Germany/Finland (EU) |
| Cloudflare Inc. (R2) | Transcript and file storage | EU jurisdiction option; US entity — SCCs/DPF |
| Stripe Payments Europe / Stripe Inc. | Payments | EU/US — SCCs/DPF |
| OpenRouter, Inc. | AI request routing (every LLM call) | US — SCCs/DPF, zero-data-retention routing setting [confirm at provisioning] |
| Google LLC (Gemini API) | AI text processing — default model tiers | US — SCCs/DPF, paid-tier no-training terms [confirm at provisioning] |
| Anthropic PBC | AI text processing — escalation model tier | US — SCCs/DPF, zero-retention API configuration [confirm at provisioning] |
| Discord Inc. | The platform itself | US — Discord's own terms apply |
Where we act as processor for an EEA-established community owner, that transfer relies on the Standard Contractual Clauses (2021/914, module 2, controller to processor). Onward transfers to the subprocessors above rely on an adequacy decision (EU–US Data Privacy Framework where the subprocessor is certified) or on the Standard Contractual Clauses, with supplementary measures where required. The table above is the current subprocessor list — this document's own version header is the source of truth for when it last changed; owners are notified of changes per the DPA.
6. Your rights
Access, rectification, erasure, restriction, portability, objection — via
/gdpr export and /gdpr delete in any server running FiveBot, via the
community owner, or via [email protected]. Complaints: your local supervisory
authority. We have no establishment in the EEA, so the GDPR one-stop-shop does
not apply — there is no single lead authority for us, and you may complain to
the authority where you live.
What erasure means here, honestly: erasure removes you — your message content, form answers, comments, and identifiers (including derived search indexes and AI embeddings) are deleted or irreversibly pseudonymized. The events (that a ticket existed, its dates, category, and outcome) remain, under a stable pseudonym, because the community owner has a legitimate interest in their moderation history. Backups age out within 14 days; data restored from backup is re-deleted by procedure.
7. Security
Row-level isolation between communities enforced in the database; encryption in transit everywhere and at rest for secrets (envelope encryption, keys in KMS); pseudonymization of cross-community identifiers with a protected key; access limited to the operator; audit logs of configuration changes. Breach notification per GDPR Articles 33/34.
8. Children
Discord requires users to be 13+ (higher in some countries). The Service does not knowingly process data of children below Discord's minimum age. Communities aimed at children should not enable Bodycam at all. Voice recording proceeds on notice and continued participation (§4), which is a mechanism that assumes the person can consent for themselves; the notice therefore tells anyone who cannot to leave the channel and ask for the conversation in text, and the community owner remains responsible for not recording people who cannot agree to it.
9. Cookies
The website uses six cookies and no third-party ones. Nothing here follows you to another site, and there is no analytics, advertising or tracking product running on these pages at all.
| Cookie | What it is for | How long | Asked for? |
|---|---|---|---|
| Sign-in session | Keeps you signed in to the dashboard | Session | No — the service cannot work without it |
fb_currency |
Which currency prices are shown in | ~180 days | No — an interface preference |
fb_seen_intro |
So the opening animation plays once, not on every visit | ~180 days | No — an interface preference |
fb_rail |
Whether your dashboard sidebar is folded | ~180 days | No — an interface preference |
fb_consent |
Your answer to the banner below | ~180 days | No — it records the choice itself |
fb_ref |
Which affiliate link brought you here, so their referral is credited | 1 hour | Yes |
fb_ref is the only one that needs consent, and it is the only thing the
banner's Only necessary withholds. Choosing it does not degrade anything
else: you stay signed in, your currency and layout are still remembered, and
the site behaves identically. The banner reappears when the recorded answer
is about six months old, so a choice made once is not treated as a choice
made forever.
10. Changes
Material changes are announced 14 days in advance in the dashboard. Version history is preserved.
Contact / controller: SDN Ventures LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA, [email protected] No Data Protection Officer is designated — none is required at this processing scale under Art. 37 GDPR; this is reassessed if that changes. No Art. 27 GDPR representative in the EU has been appointed yet. We are stating that rather than implying otherwise; it is being addressed, and this section is updated with the representative's name and address when it is.